---
id: CVE-2026-103507
title: >-
  Perforce P4 Search prior to 2026.4.2 does not restrict file paths written
  through its logging configuration interface
summary: >-
  Perforce P4 Search prior to 2026.4.2 does not restrict file paths written
  through its logging configuration interface. An attacker holding the service
  authentication token can write arbitrary files on the host, potentially
  leading to cod…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-73
vendor: Perforce
product: P4Search
affected:
  - P4Search <= 2026.4.1
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T09:17:06.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103507'
references:
  - url: >-
      https://portal.perforce.com/s/cve/a91Qi000003FE49IAG/arbitrary-filewrite-via-log-configuration-path-in-p4search
    label: security@puppet.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-05T09:16:17.871Z'
---

## Overview

Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
